TP-Link Issues Urgent Patch for Archer Routers Command Injection Flaws

TP-Link has announced critical patches for three severe command injection vulnerabilities impacting several Archer routers—BE800 V1, BE3600 V1, and AX75 V1. These flaws allow attackers to execute system commands with root privileges, possibly taking full control of the router and linked local devices. The updates, covering firmware fixes, address three CVEs: CVE-2026-9254, CVE-2026-16348, and CVE-2026-78541. ([cybersecuritynews.com](https://cybersecuritynews.com/tp-link-archer-command-injection-flaw/))

The Vulnerabilities Explained

The first flaw, CVE-2026-9254, exists in the parental‐control feature and doesn’t require any login. It allows attackers connected to the local network to inject operating‐system commands via insufficient filtering of special characters. Once exploited, it grants root‐level execution rights. It has been assigned a CVSS v4.0 score of 8.7, placing it in the High severity category. ([cybersecuritynews.com](https://cybersecuritynews.com/tp-link-archer-command-injection-flaw/))

The second issue, CVE-2026-16348, is found in the VPN subsystem of the Archer BE800 V1. Unlike the first, it demands administrative credentials. However, once inside, an attacker can use shell metacharacters over the VPN connection to execute arbitrary commands as root. It carries a CVSS 4.0 rating of 8.5. ([cybersecuritynews.com](https://cybersecuritynews.com/tp-link-archer-command-injection-flaw/))

The third flaw, CVE-2026-78541, is a stored command injection in the parental‐control module of the BE3600 V1 router. An authenticated admin can store malicious profile names containing shell characters. These inputs lie dormant until the router’s cloud reporting system processes them, where they can trigger arbitrary root commands. This is also rated High with an 8.5 CVSS v4.0 score. ([cybersecuritynews.com](https://cybersecuritynews.com/tp-link-archer-command-injection-flaw/))

Who’s Affected & What’s Fixed

Affected products are Archer BE800 V1, BE3600 V1, and AX75 V1. TP-Link has released firmware updates to plug these holes. For example, BE800 gets version 1.4.2 Build 260708; BE3600 gets 1.2.6 Build 20260617; AX75 gets 1.1.6 Build 260716. Users are encouraged to verify their router model, check they’re running one of these patched firmware builds, and apply updates immediately. ([cybersecuritynews.com](https://cybersecuritynews.com/tp-link-archer-command-injection-flaw/))

Additionally, default administrator credentials should be changed. Administrators should also limit router management to known devices and disable unnecessary remote administration features. Monitoring logs for strange behavior or unknown outbound traffic can also catch malicious activity early. ([cybersecuritynews.com](https://cybersecuritynews.com/tp-link-archer-command-injection-flaw/))

These flaws threaten core security goals—confidentiality, integrity, availability—since attackers with root access can manipulate, snoop or disrupt network traffic. ([cybersecuritynews.com](https://cybersecuritynews.com/tp-link-archer-command-injection-flaw/))

Firmware updates are already available via TP-Link’s regional support channels. Users should confirm the hardware revision on their unit to avoid installing incorrect firmware, which could create more risk. ([cybersecuritynews.com](https://cybersecuritynews.com/tp-link-archer-command-injection-flaw/))

These three vulnerabilities represent a serious risk, particularly since one requires no user interaction. Unauthorized root command execution opens the door to persistent backdoors, credential theft, lateral movement within networks, and even compromised cloud reporting. ([cybersecuritynews.com](https://cybersecuritynews.com/tp-link-archer-command-injection-flaw/))

Why this matters: routers are the nerve center of internet security in homes and small businesses. When they’re compromised, every device connected becomes vulnerable. TP-Link’s speedy firmware rollout is good—but only a patch; the real defense is proactive policing: keep firmware up to date, eliminate weak credentials, limit access, and monitor closely. Attackers will exploit network blind spots, so vigilance must match the threat level.